Permission is not consent.It is only access.
The operating system asks if you may. The Act asks why.
In one line: No, not by itself. A permission grants technical access. DPDPA requires a notice of the purpose and consent that is free, specific, informed and unambiguous. Apps should show their own notice alongside permissions.
‘Allow’ opens the door. It does not tell the customer what you will do inside.
The scene
The permission screen appeared before the customer had typed her name. Contacts, SMS, location, storage. She tapped Allow four times because the loan was urgent. Six months later she asked the app what it knew about her. The answer ran to eleven categories she had never heard of.
Where the thinking breaks
What regulators already said
The RBI's digital lending framework already restricts lending apps from accessing contacts, media and call logs beyond one-time needs. DPDPA adds the general rule: necessity for the stated purpose.
Monday morning
- 01List every permission your app requests.
- 02Write the purpose for each in one line a customer would understand.
- 03Remove any you cannot justify.
Questions, answered plainly
Is an app permission valid consent under DPDPA?
No, not by itself. A permission grants technical access. DPDPA requires a notice of the purpose and consent that is free, specific, informed and unambiguous. Apps should show their own notice alongside permissions.
Can a lending app access a borrower's contact list?
RBI's digital lending rules restrict access to contacts, media and call logs. DPDPA separately requires the data to be necessary for the stated purpose.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner